Vowelweb Ibtana
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Vowelweb Ibtana.
By the Year
In 2026 there have been 1 vulnerability in Vowelweb Ibtana with an average score of 5.3 out of ten. Ibtana did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 5.30 |
| 2025 | 0 | 0.00 |
| 2024 | 4 | 6.03 |
| 2023 | 1 | 5.40 |
| 2022 | 1 | 3.50 |
It may take a day or so for new Ibtana vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Vowelweb Ibtana Security Vulnerabilities
Ibtana Ecommerce Addons WP v0.4.7.7: Unauthorized Post Meta via AJAX
CVE-2026-1984
5.3 - Medium
- September 19, 2026
The Ibtana Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.
AuthZ
Missing Auth Vulnerability in VowelWeb Ibtana (1.2.3.3)
CVE-2024-37123
- November 01, 2024
Missing Authorization vulnerability in VowelWeb Ibtana allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through 1.2.3.3.
AuthZ
Ibtana WP Builder 1.2.4.4: Stored XSS via align attr in Gutenberg block
CVE-2024-8282
6.4 - Medium
- October 02, 2024
The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the align attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Ibtana WP Builder 1.2.3.3 Auth Bypass on Option Modification
CVE-2024-5541
5.3 - Medium
- June 18, 2024
The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it possible for unauthenticated attackers to update option values for reCAPTCHA keys on the WordPress site. This can be leveraged to bypass reCAPTCHA on the site. CVE-2024-37123 is likely a duplicate of this issue.
AuthZ
Ibtana WP Builder 1.2.2 XSS via 'ive' shortcode attrs
CVE-2023-6684
6.4 - Medium
- January 11, 2024
The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Stored XSS via unescaped shortcode attribute Ibtana WP plugin <1.1.8.8
CVE-2022-4674
5.4 - Medium
- February 06, 2023
The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack
XSS
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action
CVE-2021-25014
3.5 - Low
- February 14, 2022
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Vowelweb Ibtana or by Vowelweb? Click the Watch button to subscribe.